Carl
Member
OP
Rack & Stack
- Joined:
- May 2024
- Posts:
- 227
- From:
- Chicago, US
Got an email yesterday from someone claiming to be "upstream operations" for my provider. Not my provider—my provider's provider. They said they got an abuse complaint about "scanning activity" from my /24 and wanted "to discuss before escalating to NOC."
I lease a half-rack at a regional datacenter, single 10G drop, paying for 2kW. Never had direct contact with anyone above my immediate colo. The email came from a hostnamed address that doesn't resolve to anything I can find in WHOIS.
Is this normal? Feels like a social engineering attempt but the details were partially correct—wrong date for the alleged scan, right IP block.
visit twice: install and decom
danfra
Member
- Joined:
- Jun 2024
- Posts:
- 159
- From:
- Frankfurt, DE
Not normal. Legitimate Tier 2 contact goes through your provider, not around them. Bypass chain of custody suggests either:
- compromised ticketing system at your colo
- WHOIS scrape with poor role account parsing
- prep for targeted followup (DDoS extortion, common after "abuse" softening)
Check headers for originating netblock. If outside your colo's ASN, likely spoofed. If same ASN, possible but still unusual. Anycast vs scrubbing context irrelevant here unless they mention mitigation services next.
mitigated 800Gbps before breakfast
haroldgsm
Member
Grumpy Old Sysadmin
- Joined:
- May 2024
- Posts:
- 329
- From:
- Ohio, US
Three weeks old domain is the smoking gun. Real upstream ops use domains registered before you were born, or at least before your current contract started. I've had two of these in the last year—both led to extortion attempts a week later. "Pay us in BTC or we escalate to your upstream." Your colo's silence is another red flag. Twenty years and I still can't get some NOCs to answer tickets inside 48 hours.
IPv4, IRC, and irssi — fight me
danfra
Member
- Joined:
- Jun 2024
- Posts:
- 159
- From:
- Frankfurt, DE
SPF pass on a fresh domain is trivial. Register domain, publish permissive SPF, send from any host that matches. The hard part is the IP block knowledge. That suggests either:
- Public BGP looking glass query
- Compromised account at your colo with customer data access
- Prior reconnaissance on your /24 (port scan, service banners)
The wrong date is interesting. Either sloppy automation or deliberate misdirection to make you correct them, establishing rapport.
mitigated 800Gbps before breakfast
haroldgsm
Member
Grumpy Old Sysadmin
- Joined:
- May 2024
- Posts:
- 329
- From:
- Ohio, US
> premium abuse handling
That's a new one. Back in my day they just threatened to null-route you until you bought "clean pipe" from their buddy's shell company.
IPv4, IRC, and irssi — fight me